Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

composer update #281

Merged
merged 2 commits into from
Jul 2, 2019
Merged

composer update #281

merged 2 commits into from
Jul 2, 2019

Conversation

nobuhiko
Copy link
Contributor

2 packages have known vulnerabilities.

pear/archive_tar (1.4.3)

smarty/smarty (v3.1.32)

nobuhiko added 2 commits June 23, 2019 09:07
Symfony Security Check Report
=============================

2 packages have known vulnerabilities.

pear/archive_tar (1.4.3)
------------------------

 * [CVE-2018-1000888][]: Potential RCE if filename starts with phar://

smarty/smarty (v3.1.32)
-----------------------

 * [CVE-2018-13982][]: Trusted-Directory Bypass via Path Traversal

[CVE-2018-1000888]: https://pear.php.net/bugs/bug.php?id=23782
[CVE-2018-13982]: https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180420-01_Smarty_Path_Traversal
@coveralls
Copy link

Coverage Status

Coverage remained the same at 42.326% when pulling 573eb28 on nobuhiko:security into 3ac54e0 on EC-CUBE:improve/php7.

@kazumiiiiiiiiiii kazumiiiiiiiiiii added this to the 2.17.0 milestone Jul 2, 2019
@kazumiiiiiiiiiii kazumiiiiiiiiiii merged commit b1932bf into EC-CUBE:improve/php7 Jul 2, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants